Skip to content

Commit 7c61fca

Browse files
Merge pull request #1065 from cwatson-cat/8-1-24-usx-toc-draft
USX TOC DRAFT 2 - under XDR so it'll build
2 parents 86ad9a4 + e9072dd commit 7c61fca

File tree

4 files changed

+332
-0
lines changed

4 files changed

+332
-0
lines changed
Lines changed: 200 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,200 @@
1+
- name: Microsoft unified security operations platform
2+
href: index.yml
3+
expanded: true
4+
items:
5+
- name: Overview
6+
items:
7+
- name: What is the Microsoft unified security operations platform?
8+
href: /defender-xdr/microsoft-365-defender ## PLACEHOLDER LINK
9+
- name: What's new
10+
href: /defender-xdr/unified-soc-platform/whats-new.md
11+
- name: Defender portal service integration
12+
items:
13+
- name: Microsoft Defender XDR
14+
href: /defender-xdr/microsoft-365-defender-portal ## Placeholder article
15+
- name: Microsoft Security Exposure Management
16+
href: /security-exposure-management/get-started-exposure-management
17+
- name: Microsoft Sentinel
18+
items:
19+
- name: Microsoft Sentinel integration
20+
href: /azure/sentinel/microsoft-365-defender-sentinel-integration?toc=/unified-soc-platform/toc.json&bc=/unified-soc-platform/breadcrumb/toc.json&tabs=defender-portal
21+
- name: Experience in the Defender portal
22+
href: /azure/sentinel/microsoft-sentinel-defender-portal?toc=/unified-soc-platform/toc.json&bc=/unified-soc-platform/breadcrumb/toc.json
23+
- name: Microsoft Defender for Cloud
24+
href: /defender-xdr/microsoft-365-security-center-defender-cloud
25+
- name: Microsoft Defender for IoT
26+
href: /defender-for-iot/microsoft-defender-iot
27+
- name: Microsoft Copilot for Security in the Defender portal
28+
href: /defender-xdr/security-copilot-in-microsoft-365-defender
29+
- name: Plan ## Leverage existing zero trust articles? One article for USX all up planning (like guide that links out).
30+
items:
31+
- name: Zero trust security ## Discuss principles around Zero Trust security, link to the Zero Trust doc set as needed.
32+
items:
33+
- name: Microsoft Sentinel and Microsoft Defender XDR
34+
href: /security/operations/siem-xdr-overview
35+
- name: Microsoft Defender XDR
36+
href: /defender-xdr/zero-trust-with-microsoft-365-defender
37+
- name: Microsoft Defender for Cloud
38+
href: /azure/defender-for-cloud/zero-trust
39+
- name: Microsoft Defender for Cloud Apps
40+
href: /defender-cloud-apps/zero-trust
41+
- name: Microsoft Defender for Identity
42+
href: /defender-for-identity/zero-trust
43+
- name: Microsoft Defender for IoT
44+
href: /azure/defender-for-iot/organizations/concept-zero-trust
45+
- name: Plan for unified security operations ## NEW article that covers specific to USX all up and link out to service topics
46+
href: /defender-xdr/prerequisites ## PLACEHOLDER LINK
47+
- name: Deploy ## Need new high level article. Put post deployment links at the end of article. Single article outlining deployment steps for Defender portal services. Point to services for more details. NEW article title: Deploy the Microsoft unified security operations
48+
Items:
49+
- name: Connect Microsoft Sentinel to Microsoft Defender
50+
href: /defender-xdr/microsoft-sentinel-onboard
51+
- name: Prevent attacks ## (Pre-breach) - Renamed from reduce risks. one article that summarizes how to do that with USX
52+
items:
53+
- name: Overview ## NEW Single article or perhaps a couple of articles that summarize our pre-breach protection philosophy, with links to relevant service articles. The article should align with the info about preventing attacks that;s in the datasheet. "Through a single portal, continuously monitor your digital environment, assess risk, and implement posture improvements using security controls across all platforms, cloud, and hybrid infrastructure".
54+
href: /azure/sentinel/sap/deployment-attack-disrupt ## PLACEHOLDER LINK
55+
- name: Microsoft Secure Score ## Write a single article or two that condenses all the info in the Protect against threats/Microsoft Secure Score section. Or because this is going away, we just link in all the articles? Or put them in reference?
56+
items:
57+
- name: Overview
58+
href: /defender-xdr/microsoft-secure-score.md
59+
- name: What's new
60+
href: /defender-xdr/microsoft-secure-score-whats-new.md
61+
- name: Assess your security posture
62+
href: /defender-xdr/microsoft-secure-score-improvement-actions.md
63+
- name: Track your score history and meet goals
64+
href: /defender-xdr/microsoft-secure-score-history-metrics-trends.md
65+
- name: Data storage and privacy
66+
href: /defender-xdr/secure-score-data-storage-privacy.md
67+
- name: Detect threats ## Have each writer provide article and then we summarize in one article. Our outline and scope should align to datasheet: "Get visiblity into, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments"
68+
href: /azure/sentinel/threat-detection ## PLACEHOLDER LINK
69+
- name: Hunt for threats ## Seperating this out because per PM hunting might happen in different scenarios. Also wanting it higher level as advanced hunting is one of the things highlighted for USX.
70+
items:
71+
- name: Overview
72+
href: /defender-xdr/advanced-hunting-overview ## PLACEHOLDER - Need overview article about the hunting features across services. Advanced hunting, custom detections, hunts in Sentinel
73+
- name: Search with advanced hunting
74+
items:
75+
- name: Overview
76+
href: /defender-xdr/advanced-hunting-overview
77+
- name: Advanced hunting in the Microsoft Defender portal
78+
href: /defender-xdr/advanced-hunting-microsoft-defender
79+
- name: Guided and advanced modes
80+
href: /defender-xdr/advanced-hunting-modes
81+
- name: Generate KQL queries with Security Copilot
82+
href: /defender-xdr/advanced-hunting-security-copilot
83+
- name: Build hunting queries using guided mode
84+
href: /defender-xdr/advanced-hunting-query-builder
85+
- name: Work with query results
86+
href: /defender-xdr/advanced-hunting-query-results
87+
- name: Take action on query results
88+
href: /defender-xdr/advanced-hunting-take-action
89+
- name: Hunt for ransomware
90+
href: /defender-xdr/advanced-hunting-find-ransomware
91+
- name: Learn the query language
92+
href: /defender-xdr/advanced-hunting-query-language
93+
- name: Get expert training
94+
href: /defender-xdr/advanced-hunting-expert-training
95+
- name: Use shared queries
96+
href: /defender-xdr/advanced-hunting-shared-queries
97+
- name: Investigate incidents ## could be incidents, threats, posture findings. Need an overview article for USX. Current overviews (XDR/Sentinel) don't appear to be updated for USX.
98+
items:
99+
- name: Overview
100+
href: /defender-xdr/investigate-incidents ## Would need update to apply to USX. Per Dianne, this isn't XDR specific.
101+
- name: Alerts, incidents, and correlation
102+
href: /defender-xdr/alerts-incidents-correlation
103+
- name: Manage incidents
104+
href: /defender-xdr/manage-incidents
105+
- name: Investigate alerts
106+
href: /defender-xdr/investigate-alerts
107+
- name: Investigate incidents in Copilot for Security ## This article is specific to Sentinel in the context of using outside of USX and with XDR in USX. We don't think it applies to Sentinel only but need to confirm with PM. Austin thought title w/o mentioning Sentinel is misleading. We might need to leave this out of TOC or as part of plan/deploy to integrate Sentinel w/ Copilot features.
108+
href: /azure/sentinel/sentinel-security-copilot
109+
- name: Investigate with Microsoft Copilot in Microsoft Defender ## Copied entire section from XDR TOC
110+
items:
111+
- name: Overview
112+
href: /defender-xdr/security-copilot-in-microsoft-365-defender.md
113+
- name: Summarize incidents
114+
href: /defender-xdr/security-copilot-m365d-incident-summary.md
115+
- name: Run script analysis
116+
href: /defender-xdr/security-copilot-m365d-script-analysis.md
117+
- name: Analyze files
118+
href: /defender-xdr/copilot-in-defender-file-analysis.md
119+
- name: Generate device summaries
120+
href: /defender-xdr/copilot-in-defender-device-summary.md
121+
- name: Use guided responses
122+
href: /defender-xdr/security-copilot-m365d-guided-response.md
123+
- name: Generate KQL queries
124+
href: /defender-xdr/advanced-hunting-security-copilot.md
125+
- name: Create incident reports
126+
href: /defender-xdr/security-copilot-m365d-create-incident-report.md
127+
- name: Investigate entities
128+
items:
129+
- name: Overview
130+
href: /azure/sentinel/entity-pages?tabs=azure-portal
131+
- name: User entity pages
132+
href: /defender-xdr/investigate-users.md
133+
- name: Device entity pages
134+
href: /defender-xdr/entity-page-device.md
135+
- name: IP entity pages
136+
href: /defender-xdr/entity-page-ip.md
137+
- name: Respond to threats
138+
items:
139+
- name: Overview
140+
href: /defender-xdr/incidents-overview
141+
- name: Prioritize incidents
142+
href: /defender-xdr/incident-queue
143+
- name: Automatic attack disruption
144+
items:
145+
- name: Overview
146+
href: /defender-xdr/automatic-attack-disruption
147+
- name: Configure capabilities
148+
href: /defender-xdr/configure-attack-disruption
149+
- name: View results
150+
href: /defender-xdr/autoad-results
151+
- name: Review remediations in the action center
152+
href: /defender-xdr/m365d-action-center
153+
- name: Optimize your security operations
154+
items:
155+
- name: Overview
156+
href: /azure/sentinel/soc-optimization/soc-optimization-access?tabs=defender-portal
157+
- name: Interact with recommendations programatically
158+
href: /azure/sentinel/soc-optimization/soc-optimization-api
159+
- name: SOC optimization reference
160+
href: /azure/sentinel/soc-optimization/soc-optimization-reference
161+
- name: Manage your unified SOC ## Need article w/ overview about settings? What else needs to go here? Several other things like permissions and costs would get referenced by planning guide.
162+
items:
163+
- name: Manage multiple tenants ## Work will start soon to integrate Sentinel into one or more of these articles. Copied in entire section from XDR library
164+
items:
165+
- name: Overview
166+
href: /defender-xdr/mto-overview
167+
- name: Set up multi-tenant management
168+
href: /defender-xdr/mto-requirements
169+
- name: Manage incidents and alerts
170+
href: /defender-xdr/mto-incidents-alerts
171+
- name: Advanced hunting
172+
href: /defender-xdr/mto-advanced-hunting.md
173+
- name: Multitenant devices
174+
href: /defender-xdr/mto-tenant-devices.md
175+
- name: Vulnerability management
176+
href: /defender-xdr/mto-dashboard.md
177+
- name: Manage tenants
178+
href: /defender-xdr/mto-tenants.md
179+
- name: Manage endpoint security policies
180+
href: /defender-xdr/mto-endpoint-security-policy.md
181+
- name: Manage content distribution with tenant groups
182+
href: /defender-xdr/mto-tenantgroups.md
183+
- name: Configure notifications
184+
items:
185+
- name: Get incident notifications
186+
href: /defender-xdr/m365d-notifications-incidents
187+
- name: Configure alert notifications
188+
href: /defender-xdr/configure-email-notifications
189+
- name: Resources
190+
items:
191+
- name: Threat actor naming
192+
href: /defender-xdr/microsoft-threat-actor-naming
193+
- name: Identification of malware and unwanted apps
194+
href: /defender-xdr/criteria
195+
- name: Submit files for analysis
196+
href: /defender-xdr/submission-guide
197+
- name: Microsoft virus initiative
198+
href: /defender-xdr/virus-initiative-criteria
199+
- name: Microsoft security portals
200+
href: /defender-xdr/portals
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
- name: 'Microsoft Defender'
2+
tocHref: /defender/
3+
topicHref: /defender/index
4+
items:
5+
- name: 'Microsoft unified security operations platform'
6+
tocHref: /defender-xdr/unified-soc-platform/
7+
topicHref: /defender-xdr/unified-soc-platform/index
8+
- name: 'Microsoft unified security operations platform'
9+
tocHref: /security/zero-trust/
10+
topicHref: /defender-xdr/unified-soc-platform/index
11+
- name: Unified security operations platform
12+
tocHref: /defender-for-identity/
13+
topicHref: /defender-xdr/unified-soc-platform/index
14+
15+
## Microsoft Sentinel override
16+
- name: 'Microsoft Defender'
17+
tocHref: /azure/
18+
topicHref: /defender/index
19+
items:
20+
- name: 'Unified security operations platform'
21+
tocHref: /azure/sentinel/
22+
topicHref: /defender-xdr/unified-soc-platform/index
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
### YamlMime:Landing
2+
3+
title: Microsoft unified security operations platform # < 60 chars
4+
summary: The unified security operations platform brings together the full capabilities of Microsoft Sentinel, Defender XDR, and generative AI. # < 160 chars
5+
6+
metadata:
7+
title: Microsoft unified security operations platform documentation # Required; page title displayed in search results. Include the brand. < 60 chars.
8+
description: The unified security operations platform brings together the full capabilities of Microsoft Sentinel, Defender XDR, and generative AI. # Required; article description that is displayed in search results. < 160 chars.
9+
ms.service: defender-xdr #Required; use either service or product per approved list.
10+
ms.subservice: usx
11+
ms.topic: landing-page # Required
12+
ms.collection: usx-security # Optional; Remove if no collection is used.
13+
author: cwatson-cat #Required; your GitHub user alias, with correct capitalization.
14+
ms.author: cwatson #Required; microsoft alias of author; optional team alias.
15+
ms.date: 07/30/2024 #Required; mm/dd/yyyy format.
16+
17+
# linkListType: architecture | concept | deploy | download | get-started | how-to-guide | tutorial | overview | quickstart | reference | sample | tutorial | video | whats-new
18+
19+
landingContent:
20+
# Cards and links should be based on top customer tasks or top subjects
21+
# Start card title with a verb
22+
# Card
23+
- title: About the Microsoft security operations platform
24+
linkLists:
25+
- linkListType: overview
26+
links:
27+
- text: What is the Microsoft security operations platform?
28+
url: /defender-xdr/microsoft-365-defender
29+
- linkListType: whats-new
30+
links:
31+
- text: What's new in the Microsoft security operations platform
32+
url: /defender-xdr/unified-soc-platform/whats-new
33+
Lines changed: 77 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,77 @@
1+
---
2+
title: What's new in the Microsoft unified security operations platform
3+
description: Lists the new features and functionality in the Microsoft unified security operations platform
4+
search.appverid: met150
5+
ms.service: defender-xdr
6+
ms.author: cwatson
7+
author: cwatson-cat
8+
ms.localizationpriority: medium
9+
ms.date: 07/16/2024
10+
manager: dansimp
11+
audience: ITPro
12+
ms.collection:
13+
- M365-security-compliance
14+
- tier1
15+
- usx-security
16+
ms.topic: conceptual
17+
---
18+
19+
# What's new in the Microsoft unified security operations platform
20+
21+
<!--Need to define when something goes here versus other what's new articles. Maybe we just focus on updates within this library and things tied directly to USX (features that unblock onboarding, parity features with Sentinel, enhancements to core USX features?) -->
22+
23+
This article lists recent features added into the Microsoft unifed security operations platform within the Microsoft Defender portal, and new features in related services that provide an enhanced user experience in the platform.
24+
25+
The listed features were released in the last three months. For information about earlier features delivered, see our [Tech Community blogs](https://techcommunity.microsoft.com/t5/azure-sentinel/bg-p/AzureSentinelBlog/label-name/What's%20New).
26+
27+
For more information on what's new with other Microsoft Defender security products and Microsoft Sentinel, see:
28+
29+
- [What's new in Microsoft Sentinel](/azure/sentinel/whats-new)
30+
- [What's new in Microsoft Defender XDR](/defender-xdr/whats-new)
31+
- [What's new in Microsoft Defender for Office 365](/defender-office-365/defender-for-office-365-whats-new)
32+
- [What's new in Microsoft Defender for Endpoint](/defender-endpoint/whats-new-in-microsoft-defender-endpoint)
33+
- [What's new in Microsoft Defender for Identity](/defender-for-identity/whats-new)
34+
- [What's new in Microsoft Defender for Cloud Apps](/cloud-app-security/release-notes)
35+
36+
You can also get product updates and important notifications through the [message center](https://admin.microsoft.com/Adminportal/Home#/MessageCenter).
37+
38+
39+
## July 2024
40+
41+
- [SOC optimizations now generally available](#soc-optimizations-now-generally-available)
42+
- [SAP Business Technology Platform (BTP) connector now generally available](#sap-business-technology-platform-btp-connector-now-generally-available-ga)
43+
- [Microsoft unified security platform now generally available](#microsoft-unified-security-platform-now-generally-available)
44+
45+
### SOC optimizations now generally available
46+
47+
The SOC optimization experience in both the Azure and Defender portals is now generally available for all Microsoft Sentinel customers, including both data value and threat-based recommendations.
48+
49+
- **Use data value recommendations** to improve your data usage of ingested billable logs, gain visibility to underused logs, and discover the right detections for those logs or the right adjustments to your log tier or ingestion.
50+
51+
- **Use threat-based recommendations** to help identify gaps in coverage against specific attacks based on Microsoft research and mitigate them by ingesting the recommended logs and adding recommended detections.
52+
53+
The [`recommendations`](/azure/sentinel/soc-optimization/soc-optimization-api) API is still in Preview.
54+
55+
For more information, see:
56+
57+
- [Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access)
58+
- [SOC optimization reference of recommendations](/azure/sentinel/soc-optimization/soc-optimization-reference)
59+
60+
### SAP Business Technology Platform (BTP) connector now generally available (GA)
61+
62+
The Microsoft Sentinel Solution for SAP BTP is now generally available (GA). This solution provides visibility into your SAP BTP environment, and helps you detect and respond to threats and suspicious activities.
63+
64+
For more information, see:
65+
66+
- [Microsoft Sentinel Solution for SAP Business Technology Platform (BTP)](/azure/sentinel/sap/sap-btp-solution-overview)
67+
- [Deploy the Microsoft Sentinel solution for SAP BTP](/azure/sentinel/sap/deploy-sap-btp-solution)
68+
- [Microsoft Sentinel Solution for SAP BTP: security content reference](/azure/sentinel/sap/sap-btp-security-content)
69+
70+
### Microsoft unified security platform now generally available
71+
72+
Microsoft Sentinel is now generally available within the Microsoft unified security operations platform in the Microsoft Defender portal. The Microsoft unified security operations platform brings together the full capabilities of Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Copilot in Microsoft Defender. For more information, see the following resources:
73+
74+
- Blog post: [General availability of the Microsoft unified security operations platform](https://aka.ms/unified-soc-announcement)
75+
- [Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
76+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](/defender-xdr/microsoft-sentinel-onboard)
77+
- [Microsoft Copilot in Microsoft Defender](/defender-xdr/security-copilot-in-microsoft-365-defender)

0 commit comments

Comments
 (0)